Suppose we have a critical drain vulnerability that two whitehats find at the same time. One reports it to the bbp. Meanwhile when the report is being reviewed, the other whitehat executes a whitehat attack to secure the funds. Who gets the bounty πŸ‘€

Apr 15, 2026 Β· 6:46 AM UTC

8
1
41
3,781
Sort replies: Relevant Recent Liked
Replying to @zerocipher002
The second one is not a whitehat, exploit a live protocol shouldnt be done and there are risks of being frontrunned and lose all protocols money, which already happened in past
1
284
Don't many protocols accept such "whitehat" attacks?
1
133
Replying to @zerocipher002
Depends on the program rules, but typically: First reporter gets bounty Whitehat attacker might get discretionary reward Execution without coordination can get messy, even if intent was good.
1
3
335
The problem is that at the end he has the entire funds.
1
119
Replying to @zerocipher002
I think both get paid. Whitehat A gets the full official bug bounty for the responsible disclosure while Whitehat B (who actually drained & controls the funds) gets the negotiated recovery reward directly by the project.
1
1
267
So the whitehat B gets a higher one?
1
91
Replying to @zerocipher002
The one holding the money decides who gets the bounty
1
80
Replying to @zerocipher002
The MEV bot who front-runs the attack πŸ˜…
18
Replying to @zerocipher002
at some cases they are the same πŸ˜‚
74
Replying to @zerocipher002
The one who saved the funds gonna say me obviously, and the one who reported first gonna say me obviously 50/50?
131
Replying to @zerocipher002
Well, they both should get, but the second dude have advantage
55